fix(backend): report ingest correctness — propagate storage failure, 413 on oversize, global body cap (closes #23)
check / check (push) Successful in 45s
check / check (push) Successful in 45s
A buffer failure on POST /api/v1/reports now returns 500 instead of a false `ok`, so clients can retry. Decode errors split: an over-limit body returns 413 (via errors.As on `*http.MaxBytesError`), malformed JSON stays 400. A new MaxBodyBytes middleware (1 MiB default) caps every route — rejecting an oversized Content-Length up front and capping the read otherwise — so the health check and future routes are bounded too. The raw attacker-controlled geo blob is no longer logged, only its length; client_id and timestamp are length-bounded before logging. A decodeJSON handler helper is added. Panic recovery is now a local middleware routing the stack through slog as structured JSON. Storage failure uses 500: a full buffer or write error is server-side and retryable. Model: opus-4-8
This commit is contained in:
@@ -22,6 +22,13 @@ files, so merging it also closes most compliance gaps.
|
||||
|
||||
# Completed Steps
|
||||
|
||||
- 2026-09-21: report ingest correctness (issue #23): a storage failure now
|
||||
returns 500 instead of a false `ok`; oversize bodies return 413 (distinguished
|
||||
from malformed JSON, which stays 400); a `MaxBodyBytes` middleware caps every
|
||||
route, not just the report route; the raw attacker-controlled `geo` blob is no
|
||||
longer logged (only its length) and `client_id`/`timestamp` are length-bounded
|
||||
before logging; a `decodeJSON` handler helper was added; and panic recovery
|
||||
now routes the stack through slog instead of chi's plain-text stderr
|
||||
- 2026-09-21: shutdown lifecycle correctness. The process now shuts down through
|
||||
fx instead of `os.Exit`, so every component's `OnStop` runs and buffered
|
||||
reports are flushed to disk on `SIGTERM` — previously a full flush window of
|
||||
|
||||
Reference in New Issue
Block a user